ZeroHour

CVE-2026-76963

large

Missing authorization check in SAP NetWeaver AS ABAP exposes system configuration data

CVSS 3.1
4.3 medium
EPSS
<1%p6
Published
()
Modified
AI analysis

CVE-2026-76963 is a missing authorization check (CWE-862) in Application Server ABAP of SAP NetWeaver and ABAP Platform. A low-privileged authenticated user with network access to the affected system can trigger the flaw and gain unauthorized access to sensitive system configuration information, including security-relevant settings and internal system details. The impact is limited to confidentiality (CVSS 4.3 medium); integrity and availability are unaffected. Any organization running SAP NetWeaver AS ABAP or ABAP Platform is potentially affected. As of this analysis there is no known public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

What to do: Apply the corrective patch released by SAP in its September 2026 Security Patch Day for NetWeaver AS ABAP / ABAP Platform, consulting the SAP advisory for the exact versions covered. Until patched, restrict which low-privileged authenticated users can access the affected Application Server ABAP services and review roles/authorizations for over-provisioning. Check logs for unusual authenticated reads of configuration data by low-privilege users.

Affected
SAP NetWeaver Application Server ABAP
SAP ABAP Platform
Estimated exposure
largeon the order of 10,000-100,000 ABAP-based SAP system installations worldwide (exact count unknown) — SAP Application Server ABAP is the runtime for widely deployed SAP ERP/S4HANA landscapes across SAP's large enterprise customer base, and while many of these systems are internal rather than internet-exposed, the deployed population…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

SAP's September 2026 Patch Day fixes 19 notes including CVE-2026-44756 (CVSS 10.0), unauthenticated memory corruption in SAP Extended Passport Processing kernels.

SAP shipped 19 new security notes plus one update across NetWeaver, S/4HANA, Integration Suite, Commerce Cloud, and Cloud Application Programming Model. Top issues include CVE-2026-44756 (CVSS 10.0 memory corruption in SAP Extended Passport Processing across many KERNEL and Web Dispatcher versions), CVE-2026-58240 (CVSS 9.8 missing authentication in NetWeaver Message Server), CVE-2026-76969 (CVSS 9.4 credential disclosure in CAP library sap/cds-mtxs), and CVE-2026-66768 (CVSS 9.0 access control flaw in SAP GUI for Java). No exploitation is reported; organizations running affected kernels are urged to patch urgently.